*** gyee has quit IRC | 00:42 | |
*** imacdonn has quit IRC | 00:49 | |
*** yankcrime has quit IRC | 01:00 | |
*** cloudnull has quit IRC | 01:00 | |
*** tobias-urdin has quit IRC | 01:00 | |
*** Guest58757 has joined #openstack-keystone | 01:03 | |
*** imacdonn has joined #openstack-keystone | 01:09 | |
*** imacdonn has quit IRC | 01:14 | |
*** imacdonn has joined #openstack-keystone | 01:15 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:04 | |
*** hoonetorg has quit IRC | 02:04 | |
*** hoonetorg has joined #openstack-keystone | 02:17 | |
openstackgerrit | fupingxie proposed openstack/keystone master: Do not translate log messages. https://review.openstack.org/603953 | 02:23 |
---|---|---|
*** Dinesh_Bhor has quit IRC | 03:11 | |
*** Dinesh_Bhor has joined #openstack-keystone | 03:12 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add hint back https://review.openstack.org/603964 | 03:28 |
*** sapd1_ has quit IRC | 03:45 | |
*** sapd1 has joined #openstack-keystone | 03:45 | |
*** Dinesh_Bhor has quit IRC | 03:50 | |
vishakha | wxy-xiyuan: Hello. Can you pl review this test caes https://review.openstack.org/#/c/603539/ | 04:05 |
ayoung | vishakha, you know how to run just the pep8 tests? | 04:06 |
vishakha | ayoung: use command tox -epep8 | 04:08 |
ayoung | vishakha, yeah, get that test case to run clean pep, so it passes check | 04:09 |
ayoung | vishakha, also, your new test fails | 04:09 |
ayoung | SystemExit: Error while parsing rules /tmp/tmpzYxfG1/tmpJ35T2c: No JSON object could be decoded | 04:10 |
ayoung | vishakha, http://logs.openstack.org/39/603539/1/check/openstack-tox-py27/ed2cc94/testr_results.html.gz you can see the test results there. Get the tests to pass and pep8 clean. Most people won | 04:10 |
ayoung | 't bother reviewing a broken patch | 04:10 |
ayoung | OK? | 04:10 |
vishakha | ayoung: ok thanks for the response | 04:11 |
ayoung | adriant, I'm sorry I missed that meeting. I'm nort sure I understood correctly, but if you are doing rules like "don't allow if user has role noop" you are making a security hole. With a trust (which all users can create) they can drop any role they have. | 04:12 |
ayoung | and with that. I'm out. | 04:12 |
*** ayoung has quit IRC | 04:12 | |
adriant | bah, and he's gone before I can respond :P | 04:13 |
adriant | that isn't the point of the noop role, doing rules with "NOT role:noop" is a silly idea. Instead, just make all your policies require a role. No empty "auth'd only" policies. | 04:15 |
adriant | so a noop role is really just a role that fulfils only empty policies (which you'd ensure there aren't many or any of them). | 04:15 |
adriant | but... | 04:15 |
adriant | lbragstad, cmurphy: on the note of trusts and implied roles... | 04:16 |
adriant | I assume a trust can't allow you to set a role you don't actually have, but are implied to have? | 04:16 |
adriant | e.g. I have reseller_member which implies member, can I make a trust for my user with just member? | 04:16 |
adriant | if so, that's broken | 04:16 |
adriant | but I'd assume that doesn't work | 04:20 |
*** Dinesh_Bhor has joined #openstack-keystone | 04:46 | |
*** jaosorior has quit IRC | 05:03 | |
*** Guest58757 is now known as cloudnull | 05:32 | |
*** shyamb has joined #openstack-keystone | 05:34 | |
*** shyamb has quit IRC | 05:39 | |
*** shyamb has joined #openstack-keystone | 05:48 | |
*** shyamb has quit IRC | 06:03 | |
*** shyamb has joined #openstack-keystone | 06:03 | |
*** Dinesh_Bhor has quit IRC | 06:08 | |
*** Dinesh_Bhor has joined #openstack-keystone | 06:15 | |
*** jaosorior has joined #openstack-keystone | 06:25 | |
*** Dinesh_Bhor has quit IRC | 06:38 | |
*** belmoreira has joined #openstack-keystone | 06:39 | |
wxy-xiyuan | vishakha: lol, like ayoung said, please let the CI pass first. If you have problem about that, please let me know again. :) | 06:42 |
*** Dinesh_Bhor has joined #openstack-keystone | 06:42 | |
*** shyamb has quit IRC | 06:55 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add hint back https://review.openstack.org/603964 | 06:59 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Adding test case for MappingEngineTester https://review.openstack.org/603539 | 07:01 |
*** rcernin has quit IRC | 07:02 | |
openstackgerrit | Tao Li proposed openstack/keystone master: Use uuidutils instead of uuid.uuid4() https://review.openstack.org/603542 | 07:03 |
vishakha | wxy-xiyuan: yes it is not cleared yet. Uploaded a new patch for it. | 07:03 |
*** shyamb has joined #openstack-keystone | 07:08 | |
*** Dinesh_Bhor has quit IRC | 07:39 | |
*** shyamb has quit IRC | 07:41 | |
*** shyamb has joined #openstack-keystone | 07:41 | |
*** Dinesh_Bhor has joined #openstack-keystone | 07:49 | |
*** Dinesh_Bhor has quit IRC | 07:54 | |
*** shyamb has quit IRC | 07:59 | |
*** Dinesh_Bhor has joined #openstack-keystone | 08:01 | |
*** jaosorior has quit IRC | 08:12 | |
*** yankcrime has joined #openstack-keystone | 08:17 | |
*** nick_kar has quit IRC | 08:29 | |
*** nick_kar has joined #openstack-keystone | 08:30 | |
*** shyamb has joined #openstack-keystone | 08:34 | |
*** jaosorior has joined #openstack-keystone | 08:58 | |
*** Dinesh_Bhor has quit IRC | 09:01 | |
*** Tahvok has left #openstack-keystone | 09:19 | |
*** Dinesh_Bhor has joined #openstack-keystone | 09:19 | |
*** tobias-urdin has joined #openstack-keystone | 09:35 | |
*** belmoreira has quit IRC | 09:38 | |
*** jaosorior has quit IRC | 09:53 | |
*** jlvillal has quit IRC | 09:54 | |
*** jlvillal has joined #openstack-keystone | 09:54 | |
*** shyamb has quit IRC | 09:59 | |
*** pcaruana has joined #openstack-keystone | 10:04 | |
*** Dinesh_Bhor has quit IRC | 10:13 | |
*** Dinesh_Bhor has joined #openstack-keystone | 10:15 | |
*** Dinesh_Bhor has quit IRC | 10:16 | |
*** shyamb has joined #openstack-keystone | 10:17 | |
*** pgaxatte has quit IRC | 10:35 | |
*** jlvillal has quit IRC | 10:50 | |
*** jlvillal has joined #openstack-keystone | 10:53 | |
*** belmoreira has joined #openstack-keystone | 10:57 | |
*** jaosorior has joined #openstack-keystone | 10:58 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: POC: Add Open Policy Agent driver https://review.openstack.org/604038 | 11:06 |
*** shyamb has quit IRC | 11:12 | |
*** shyamb has joined #openstack-keystone | 11:12 | |
*** pcaruana has quit IRC | 11:15 | |
*** shyamb has quit IRC | 11:16 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: POC: Add Open Policy Agent driver https://review.openstack.org/604038 | 11:16 |
*** pcaruana has joined #openstack-keystone | 11:20 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: POC: Add Open Policy Agent driver https://review.openstack.org/604038 | 11:23 |
*** pcaruana has quit IRC | 11:32 | |
*** pcaruana has joined #openstack-keystone | 11:39 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: POC: Add Open Policy Agent driver https://review.openstack.org/604038 | 11:40 |
*** mattgo has joined #openstack-keystone | 11:47 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: POC: Add Open Policy Agent driver https://review.openstack.org/604038 | 11:48 |
*** pcaruana has quit IRC | 11:50 | |
*** shyamb has joined #openstack-keystone | 11:57 | |
*** jdennis has quit IRC | 12:18 | |
*** aloga has quit IRC | 12:35 | |
*** aloga has joined #openstack-keystone | 12:36 | |
lbragstad | o/ | 12:52 |
*** raildo has joined #openstack-keystone | 12:58 | |
*** shyamb has quit IRC | 13:07 | |
*** shyamb has joined #openstack-keystone | 13:07 | |
*** shyamb has quit IRC | 13:23 | |
*** jistr is now known as jistr|call | 13:32 | |
*** jdennis has joined #openstack-keystone | 14:04 | |
samueldmq | o/ | 14:27 |
samueldmq | cmurphy: hi, sorry for late reply | 14:27 |
samueldmq | cmurphy: applications are now open (since yesterday) and new projects can be submitted any time until October 9th according to the last agenda I have | 14:28 |
samueldmq | cmurphy: I will update the info in that link, thanks! | 14:28 |
*** jistr|call is now known as jistr | 14:34 | |
gagehugo | samueldmq o/ | 15:02 |
*** dklyle has joined #openstack-keystone | 15:04 | |
*** etp has joined #openstack-keystone | 15:05 | |
*** dave-mccowan has quit IRC | 15:25 | |
*** dave-mccowan has joined #openstack-keystone | 15:31 | |
*** mattgo has quit IRC | 15:39 | |
kmalloc | adriant: sounds like something keystone specific. What is the point of noop in Nova? | 15:45 |
kmalloc | adriant: if it is just to setup things like mfa, we can do it as a system-scope, and I can modify our enforcer for some calls. | 15:46 |
kmalloc | adriant: and a system scope without role, should be sufficient for that. (aka non escalated permissions, but not project scoped) | 15:46 |
kmalloc | Generally I don't like an explicit or implicit noop role. | 15:47 |
kmalloc | I generally want to down play unscoped tokens anyway with the advent of system scope. | 15:48 |
*** gyee has joined #openstack-keystone | 15:58 | |
*** mattgo has joined #openstack-keystone | 16:58 | |
knikolla | o/ | 17:20 |
knikolla | today is one of those meeting after meeting days :( | 17:20 |
*** dave-mccowan has quit IRC | 17:44 | |
*** dave-mccowan has joined #openstack-keystone | 17:46 | |
gagehugo | knikolla: yup | 17:47 |
knikolla | gagehugo: did you get my nintendo friend request? | 17:49 |
gagehugo | yup! | 17:49 |
*** mattgo has quit IRC | 18:01 | |
samueldmq | gagehugo: o/ | 18:50 |
*** raha has joined #openstack-keystone | 19:07 | |
raha | Could anyone recommend me a good book about RESTfull api? | 19:08 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Add docs for developers testing APIs https://review.openstack.org/604192 | 19:09 |
*** belmoreira has quit IRC | 19:35 | |
* raha | 19:36 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone-specs master: [DRAFT] Refreshable Application Credentials https://review.openstack.org/604201 | 19:49 |
* knikolla considers renewable vs refreshable | 19:52 | |
*** raha has quit IRC | 20:19 | |
*** raildo has quit IRC | 21:02 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement scope_type checking for credentials https://review.openstack.org/594547 | 21:30 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove obsolete credential policies https://review.openstack.org/597187 | 21:30 |
lbragstad | zuul's gettin' a workout today | 21:44 |
* lbragstad hands zuul a bottle of water and a towel | 21:44 | |
lbragstad | that credentials patch should pass 100% now | 21:52 |
lbragstad | needed to redo a couple tests | 21:52 |
lbragstad | but it should be good to review | 21:52 |
*** DinaBelova has quit IRC | 22:04 | |
*** DinaBelova has joined #openstack-keystone | 22:06 | |
adriant | kmalloc: did you by chance read the email I sent to follow up for Adam? | 22:14 |
cmurphy | thanks samueldmq | 22:14 |
adriant | The use case we have right now that customers are asking for: "I have a backup project, and I want to create a container per person, and give them access only to that container. They need to be able to auth, and scope to that project, but not do anything else in it other than see their own container." To achieve this is part Keystone's auth with ro | 22:18 |
adriant | les, and part Swift ACLs. But with nova and other services having rules that amount to: "any role on a project lets you access all project resources" that makes it hard. | 22:18 |
adriant | https://github.com/openstack/nova/blob/master/nova/policies/base.py#L31< is the default style role for Nova, and from memory, most of the other projects do it much the same | 22:20 |
adriant | and glance: https://github.com/openstack/glance/blob/master/etc/policy.json which I assume then does per project filtering in code (and likely has hardcoded checks for is_admin?). | 22:22 |
adriant | The issue is that any new roles created, by default when assigned to a project, give a user full access to all project resources. | 22:22 |
adriant | so what the role is doesn't matter beyond is the role admin | 22:23 |
adriant | yeah, admin_or_owner is pretty much the norm: https://github.com/openstack/cinder/blob/master/cinder/policies/base.py#L27 | 22:25 |
*** spsurya has quit IRC | 22:48 | |
*** david-lyle has joined #openstack-keystone | 22:49 | |
*** spsurya has joined #openstack-keystone | 22:50 | |
*** dklyle has quit IRC | 22:51 | |
*** rcernin has joined #openstack-keystone | 22:53 | |
*** andreykurilin has quit IRC | 23:34 | |
*** andreykurilin has joined #openstack-keystone | 23:35 | |
*** rcernin has quit IRC | 23:36 | |
*** rcernin has joined #openstack-keystone | 23:36 | |
*** gyee has quit IRC | 23:41 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!